Cyber Insurance

Insurance Advice for Australian Businesses

Contact An Adviser

Technology is part of almost every business now, but the way businesses depend on it varies enormously. For one business, the biggest concern may be confidential customer information. For another it may be losing access to the systems needed to trade.

Cyber insurance is one way of transferring some of the financial consequences of a cyber incident. It doesn’t prevent an attack, replace good cyber security or guarantee that every cyber-loss will be covered.

The useful question is whether the cover available reflects the cyber exposures that matter to your business.

What is Cyber Insurance?

Cyber insurance is designed to respond to certain financial losses and liabilities arising from cyber incidents.

Depending on the policy, it may help with the cost of investigating an incident or restoring affected systems. Some policies may provide cover for business interruption following an insured cyber event.

There may be protection for certain privacy-related liabilities or the cost of responding to a data breach. The detail varies considerably between insurers. Two policies that appear similar can respond differently when it comes to ransomware, incidents affecting external technology providers or interruption to your systems.

That’s why cyber insurance is worth comparing on more than the premium and headline limits.

Cyber Risk in Australia

Cybercrime affects organisations of all sizes. In the 2024-2025 financial year, the Australian Signals Directorate’s Australian Cyber Security Centre received more than 84,700 cybercrime reports, or roughly one report every six minutes. The average self-reported cost per cybercrime report for businesses was $80,850, although individual losses vary significantly.

Privacy breaches remain significant. The Office of the Australian Information Commissioner received 1,205 data breach notifications during 2025, the highest annual number since mandatory data breach reporting began in 2018.

Those figures don’t mean every business is likely to suffer a major cyber loss. They do show why cyber exposure is worth understanding rather than dismissing as an issue reserved for large corporations.

For more background on the wider business impact, read ‘4 Reasons to Manage Cyber Security Risk’

Cyber Risk Looks Different From One Business to Another

The amount of data a business holds is only part of the picture.

A professional services firm may rely heavily on confidential client information. A manufacturer could be more concerned about production stopping because critical systems are unavailable.

A club might depend on payment systems and member databases, while a health organisation can have additional privacy obligations because of the information it holds. Even a small business can be highly dependent on email, cloud software and online banking.

New technology can create different dependencies. If your organisation is introducing AI tools, our article ‘5 Business Risks to Consider When Using Artificial Intelligence’ looks at some of the data, third party technology and insurance considerations involved.

Understanding your technology dependencies improves the insurance conversation.

Common Types of Cyber Incidents

Cyber incidents don’t all look the same.

Ransomware & Cyber Extortion

Ransomware can prevent a business from accessing its systems or data. Attackers may steal information and threaten to release it unless payment is made.

The financial impact can extend beyond the ransom itself. Systems may need to be investigated or rebuilt, and the business may be unable to operate normally while that work takes place.

For a closer look at how those attacks work, read ‘What is Human-Operated Ransomware’.

For practical prevention ideas see ‘Ransomware: 5 Ways to Protect Your Business’.

Data Breaches

A data breach can occur when personal or confidential information is lost, accessed without authority or disclosed to someone who should not have it.

Sometimes the cause is a sophisticated attack. Other breaches begin with something much simpler, such as compromised login details or human error.

Not every breach is legally notifiable. The circumstances and likely impact on affected individuals need to be considered.

Social Engineering & Business Email Compromise

Some cybercrime targets people rather than technology.

An attacker may impersonate a colleague, executive or supplier and try to persuade someone to transfer money or reveal information. These incidents can be particularly difficult to spot because the communication may appear genuine.

Our article, ‘What is Social Engineering and Why is it so Effective?’ explains some of the techniques involved.

System Disruption

Sometimes the biggest loss isn’t stolen information.

If employees cannot access critical systems, a business may struggle to operate even when no personal data has been compromised. That distinction becomes important when comparing cyber policies because business interruption cover can vary considerably.

Cyber Insurance hands on keyboard and security symbols

What Cyber Insurance May Cover

Cyber policies differ. However, cover generally falls into two broad areas.

  1. First-party cover which deals with certain losses experienced by your business
  2. Third-party cover which deals with certain claims or liabilities involving other people or organisations

Not every policy includes every type of cover below.

  • Incident Response & Investigation

When an incident occurs, one of the first questions is, ‘what happened?’.

A cyber policy may provide access to specialist incident-response services and cover certain investigation costs. Some insurers have preferred response providers or require you to follow particular procedures.

Knowing how the process works before an incident occurs can make things easier if you ever need to use the policy.

  • Data & System Restoration

A cyberattack can leave data corrupted or systems unavailable.

Depending on the policy, cover may extend to certain costs involved in restoring data or rebuilding affected systems. Policy requirements around backups and restoration can differ between insurers.

  • Business interruption

A business doesn’t need to lose data to suffer a substantial cyber loss. If important systems are unavailable, employees may be unable to work, or customers may be unable to transact.

Some policies provide business interruption cover following specified cyber events. Check the waiting period and how the insurer calculates the loss. The maximum period for which the cover responds can make a difference.

  • Privacy Breach Response

A privacy breach can involve investigation costs and legal questions about whether notification is required.

Some cyber policies provide access to specialist legal or privacy support. Certain notification and communication costs may be covered. The precise response depends on the circumstances of the breach.

  • Cyber Extortion

Some cyber policies provide access to specialist advisers during a cyber-extortion incident.

Cover may extend to certain costs associated with managing the event. Whether a ransom payment itself is covered is a separate question. Policy terms vary, and legal restrictions may affect whether a payment is lawful.

  • Third-Party Liability

A cyber incident may lead to a claim from a customer or another organisation.

A cyber policy may provide cover for certain defence costs or liabilities arising from an insured privacy or security event. The scope of that protection depends on the wording.

  • Regulatory Investigations

A serious privacy or cyber incident can attract regulatory attention.

Some policies provide cover for certain costs involved in responding to an investigation. Fines and penalties are more complicated. Whether they can be insured depends on the circumstances, applicable law and policy wording, so they shouldn’t be assumed to be automatically covered.

Australian Privacy Obligations

Cyber insurance doesn’t determine your privacy obligations.

The Notifiable Data Breaches scheme applies to organisations and agencies that are covered by the Privacy Act. An eligible breach generally involves a breach that is likely to cause serious harm to one or more individuals and where remedial action has not removed that likelihood.

Who Is Covered by the Notifiable Data Breaches Scheme?

The often quoted $3 million turnover threshold doesn’t tell the whole story. Many businesses with annual turnover above $3 million are included, but some smaller organisations are too.

Examples include private health service providers and certain organisations that deal in personal information. Businesses shouldn’t assume they fall outside the Privacy Act purely because of their size.

Assessing a Suspected Breach

If there are grounds to suspect an eligible data breach, covered entities must take reasonable steps to assess it. The assessment should generally be completed within 30 calendar days, with the OAIC encouraging organisations to treat that as a maximum rather than a target.

If an eligible breach is confirmed, notification requirements may apply. Legal or privacy advice should be obtained where there is uncertainty about an organisation’s obligations.

Ransomware Payment Reporting

Australia has specific reporting requirements for certain ransomware and cyber-extortion payments.

An entity carrying on business in Australia is captured where its annual turnover for the previous financial year is $3 million or more. Certain critical infrastructure entities are also included.

Where the regime applies, a report must generally be made within 72 hours of the payment being made, or of the organisation becoming aware that a payment was made on its behalf.

The requirement relates to payments, not simply receiving a demand. It’s separate from whether an insurance policy responds to the incident.

How Cyber Insurance Claims Work

The first thing to know is that cyber policies usually contain notification requirements. If you become aware of an incident that may involve your policy, it’s generally better to contact your insurance adviser and insurer promptly rather than waiting until the entire event has been investigated.

The insurer may have an incident response process it expects you to follow.

Some parts of a cyber policy may operate on a claims-made basis, while others may deal with direct losses. Take note of the notification provisions in your policy. If you’re moving from one insurer to another, known incidents, circumstances and continuity of cover should be considered before the existing policy ends.

What Cyber Insurance May Not Cover

Cyber insurance isn’t designed to cover every technology problem. Common limitations can include matters the insured knew about before the policy began.

Some losses may fall outside the events defined in the policy. Security representations made during the application process can be relevant.  Instead of relying on a generic list of exclusions, read the wording for the policy being considered.

  • War & State-Sponsored Cyber Events

Cyber war exclusions have become an important feature of the cyber insurance market. The wording can be complicated and varies between insurers. Check the individual policy to see what is and is not covered.

  • Ransom Payments

Not every policy covers ransom payments. Even where cyber-extortion cover is available, insurer approval or other conditions may apply. There can also be legal considerations. Legal advice should be obtained before making a payment.

  • Inaccurate Information Provided to an Insurer

Cyber insurance applications increasingly ask detailed questions about a business’ security arrangements. Answer those questions accurately. If you’re unsure whether a particular technical control is in place, check with your IT provider rather than guessing.

Cyber Security Still Matters

Insurance and cyber security perform different jobs. Security measures aim to reduce the likelihood or impact of an incident. Insurance may transfer some of the financial consequences when a covered event occurs.

An insurance policy shouldn’t be treated as a substitute for good security.

Technical questions about the controls your business should implement are best handled by an appropriately qualified IT or cyber-security specialist.

What Insurers May Ask About

Cyber insurers usually want to understand how an organisation protects its systems before deciding whether to offer cover and on what terms.

Multi-factor authentication is commonly considered. Backups are important too.

Depending on the business, insurers may ask more detailed questions about access to sensitive systems, or how the organisation would respond to an incident. The questions vary by industry and size.

If you don’t know the answer to a technical underwriting question, ask whoever manages your IT systems.

For a broader explanation of why these issues matter, see ‘4 Reasons to Manage Cyber Security Risk’.

When Might Cyber Insurance Be Worth Considering?

There isn’t a single rule based on business size. Start with what would happen if your technology stopped working. Could you still trade?

Think about the information you hold as well. A breach involving sensitive personal information can create a very different problem from losing access to an ordinary internal file. Contracts can influence the decision. Some organisations are asked to hold cyber insurance before working with particular customers or suppliers.

The aim isn’t to conclude that every business must buy a policy. It’s to understand the exposure and decide whether insurance is a useful way of transferring part of the risk.

When Might Cyber Insurance Be A Lower Priority?

Cyber insurance doesn’t necessarily sit at the top of every organisation’s insurance priorities.

A very small business with limited personal information and relatively little dependence on technology may have a different exposure from an online business that can’t operate without its systems. Even then, it is worth thinking through the email, banking and cloud software your business may use before deciding the cyber exposure is negligible.

The decision should sit alongside the other risks competing for the insurance budget.

How Much Cyber Insurance Cover Do You Need?

There isn’t a standard limit that suits every business. Revenue alone doesn’t answer the question.

Consider how long the business could operate if important systems were unavailable. Think about the type and amount of information held and what it could cost to respond if that information were compromised. Contractual requirements may also set minimum limits.

Rather than beginning with an arbitrary figure such as $500,000 or $1 million, work backwards from the consequences of a realistic incident. An insurance adviser can then explain the limits available and how they affect the policy.

How Much Does Cyber Insurance Cost?

There isn’t a useful standard price for cyber insurance. Premiums depend on the nature of the organisation and the cover being requested. An insurer will also consider its assessment of the cyber exposure. Security controls can affect underwriting, but they don’t guarantee a particular premium or outcome.

For that reason, publishing a generic premium range can be misleading. The price may bear little relationship to the terms available to a particular business.

Choosing Between Cyber Insurance Policies

Start with the cover rather than the price. Look at the events that trigger the policy. Then look at the exclusions.

Sub-limits can matter because a policy with a $1 million limit doesn’t necessarily provide $1 million for every type of loss. The incident response service is worth understanding too.

If an event happens late at night, who do you contact? Does the insurer provide access to specialists? Are you expected to obtain approval before appointing your own providers? Those practical details can be very useful.

Hands on computer depicting cyber security for insurance purposes

Frequently Asked Questions

Does cyber insurance cover ransomware?

It can. Cyber policies may cover certain costs associated with a ransomware incident. That can include investigation or system restoration, depending on the policy. Business interruption may also be available following particular events.

Some policies include cyber-extortion cover, but ransom payments are treated differently across the market. Check the policy rather than assuming every ransomware event will be covered.

Does general liability insurance cover cyber incidents?

General liability insurance is generally designed around liabilities such as bodily injury and property damage. It shouldn’t be assumed to provide the same protection as a dedicated cyber policy.

If you’re unsure what protection already exists elsewhere in your insurance program, check the policies before deciding whether cover is needed or ask your insurance adviser for a risk and insurance review.

What if we already have strong IT security?

That’s a good thing, but security and insurance perform different roles. Strong security may reduce the likelihood or impact of an attack. Cyber insurance deals with certain financial consequences if an insured event still occurs.

Security controls may also influence underwriting, but they don’t guarantee cheaper premiums or broader cover.

How is a cyber insurance premium calculated?

There isn’t a single formula. The insurer will consider the type of business and the cover being requested. The business’ reliance on technology is also relevant, as is the information the business holds and its previous cyber claims experience.

Cyber-security controls may influence the insurer’s assessment. That’s why two businesses with similar turnover can receive quite different policy terms.

How do I compare cyber insurance policies?

Don’t compare premium alone. Start with the cover provided and the events that trigger it. Look at the exclusions and sub-limits. Then consider what happens if you need to use the policy.

Access to specialist incident response services can be particularly valuable during a cyber event.

Does cyber insurance cover business interruption?

It may. Some policies provide business interruption cover following specified cyber incidents. Waiting periods vary. The way the financial loss is calculated can vary too. Check how long the policy can respond and whether incidents involving third-party technology providers are treated differently.

Does cyber insurance cover data breaches?

It may cover certain costs or liabilities arising from an insured data breach. That could include specialist response costs or some privacy-related liabilities, depending on the policy.

Insurance doesn’t determine whether a breach needs to be reported under the Privacy Act. That’s a separate legal question.

Is cyber insurance compulsory in Australia?

There is no general requirement for every Australian business to purchase cyber insurance. A contract may require it.

Some organisations may operate under specific regulatory cyber-security requirements, but those obligations don’t necessarily mean cyber insurance itself is mandatory. Whether the cover is appropriate depends on the organisation and its circumstances.

Can you get cyber insurance after a previous cyber incident?

Potentially. A previous incident doesn’t automatically mean insurance will be unavailable. The insurer is likely to ask what happened and what has changed since – such as security improvements.

The previous incident should be disclosed accurately when required. The insurer can then decide whether it is prepared to offer cover and on what terms.

Cyber Insurance Across Different Industries

Cyber exposure changes with the way a business operates. For professional services firms, confidential client information can be particularly important. Manufacturers may be more concerned about systems that keep production moving.

Technology businesses can have significant dependencies on their platforms and third-party infrastructure. Clubs may depend on member information and payment systems.

Not-for-profit and health organisations can also hold particularly sensitive information.

For more industry-specific insurance considerations visit our industry pages.

For independent cyber-security guidance, you can also use the Australian Cyber Security Centre resources.

Understanding Your Insurance Options

If you’ve decided to investigate cyber insurance, an insurance adviser can help you understand your cyber risk exposure, the available policies and where the wording differs.

If you’re not sure whether cyber insurance is a priority, that’s a reasonable place to start. The purpose of the discussion should be to understand the exposure, the protection already in place and the options available.

You can then decide whether transferring some of that risk to insurance makes sense for your business.

If you would like a no-obligation risk and insurance review tailored to your business, contact Clear Insurance on 1300 721 132 or email info@clearinsurance.com.au. Alternatively, complete our online enquiry form and an adviser will be in touch.


General Advice Warning

This information is general advice only. It does not take into account your objectives, financial situation, or individual circumstances. You should consider whether the information is appropriate for you and your personal circumstances before making any decision about whether to acquire cyber insurance. Before you acquire any cyber insurance policy, you should obtain and read the relevant Product Disclosure Statement from the insurer. Different policies have different coverage, exclusions, and terms. If you would like personal advice tailored to your specific situation, or if you are uncertain about your cyber insurance needs, contact an insurance adviser. Clear Insurance Pty Ltd operates under Australian Financial Services Licence 548953, ABN 41 601 916 689. For more information about our services and how we can help you, contact us or read our Financial Services Guide.

Disclaimer

The information in this guide is current as of August 2026 and reflects Australian privacy law, regulatory guidance, and market practice at that time. Cyber threats, insurance products, and regulations change regularly. You should verify current terms with your insurer and seek professional advice before making insurance decisions.